ShinyHunters Exploits Encoding Flaw to Evade WAFs and Target Oracle PeopleSoft Servers
An extortion group known as ShinyHunters has revived large‑scale attacks against Oracle PeopleSoft installations by employing a URL‑encoding technique that sidesteps existing web‑application firewall (WAF) rules designed to block the recently disclosed CVE‑2026‑35273 vulnerability.
The method works by encoding malicious payloads in a way that the firewall does not recognize as a threat, while the vulnerable PeopleSoft server still processes the request and executes the exploit. Security researchers who first observed the activity say the trick restores the gang’s ability to compromise a broad range of organizations that have not yet applied the vendor’s patch or updated their protective controls.
PeopleSoft, a suite of enterprise resource planning applications widely used in higher education, government and large corporations, was found to contain a critical flaw that allows unauthenticated attackers to execute arbitrary code on affected systems. Oracle issued a security advisory and a patch shortly after the vulnerability was disclosed, and many defenders responded by configuring WAFs to drop traffic matching known exploit patterns. ShinyHunters’ encoding workaround effectively neutralises those defensive signatures, reopening a path that had been largely closed.
Cyber‑security firms note that the resurgence of exploitation underscores a persistent challenge: even when patches are released, real‑world remediation can lag for months or years. Organizations that rely solely on signature‑based WAF rules may find themselves exposed to novel evasion techniques such as the one demonstrated by ShinyHunters. Experts advise a layered approach that includes regular patch management, behavioural monitoring, and threat‑intelligence feeds that can flag emerging encoding tricks.
The activity was first reported by BleepingComputer, which highlighted the gang’s shift from earlier ransomware‑focused campaigns to a more extortion‑oriented model that threatens to leak compromised data unless victims pay. While no new ransom demands have been disclosed, the pattern suggests that attackers will continue to leverage the PeopleSoft flaw until a substantial portion of the installed base is fully protected. Analysts expect that security vendors will update their WAF signatures to account for the encoding bypass, and that organizations will need to verify that those updates are correctly deployed across their environments.
Comments (0)
Be the first to comment.
Join the discussion